Total vulnerabilities in the database
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.
CVSS v3:
CVSS v2:
CWEs: